← Back to News Iceland Security Dashboard Browse all tags
T1078

Valid Accounts

View on attack.mitre.org →

CVEs tagged with this technique (50)

CVE-2026-22769 🚨 CVSS 10.0 Dell / RecoverPoint for Virtual Machines (RP4VMs)
Dell RecoverPoint for Virtual Machines versions prior to 6.0.3.1 HF1 contain a hardcoded credential vulnerability (CWE-798) allowing unauthenticated remote atta…
CVE-2026-20182 🚨 CVSS 10.0 Cisco / Catalyst SD-WAN
CVE-2026-20182 is a critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller and Manager, allowing unauthenticated remote attackers to o…
CVE-2026-20127 🚨 CVSS 10.0 Cisco / Catalyst SD-WAN Controller and Manager
CVE-2026-20127 is a critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller and Manager that allows unauthenticated remote attackers to…
CVE-2026-45321 🚨 CVSS 9.6 TanStack / TanStack
CVE-2026-45321 is a critical supply-chain vulnerability affecting 42 TanStack packages, including TanStack/router, where 84 malicious versions were published to…
CVE-2026-34197 🚨 CVSS 8.8 Apache / ActiveMQ
CVE-2026-34197 is a high-severity code injection vulnerability in Apache ActiveMQ (versions before 5.19.4 and 6.0.0-6.2.3) caused by improper input validation i…
CVE-2026-20128 🚨 CVSS 7.5 Cisco / Catalyst SD-WAN Manager
CVE-2026-20128 is a high-severity vulnerability in Cisco Catalyst SD-WAN Manager affecting versions prior to 20.18, allowing unauthenticated remote attackers to…
CVE-2026-6973 🚨 CVSS 7.2 Ivanti / Endpoint Manager Mobile (EPMM)
CVE-2026-6973 is a high-severity (CVSS 7.2) remote code execution vulnerability in Ivanti EPMM versions prior to 12.6.1.1, 12.7.0.1, and 12.8.0.1, caused by imp…
CVE-2026-20133 🚨 CVSS 6.5 Cisco / Catalyst SD-WAN Manager
CVE-2026-20133 is a medium severity (CVSS 6.5) information disclosure vulnerability in Cisco Catalyst SD-WAN Software caused by insufficient file system restric…
CVE-2026-20122 🚨 CVSS 5.4 Cisco / Catalyst SD-WAN Manger
CVE-2026-20122 is a medium severity vulnerability (CVSS 5.4) in Cisco Catalyst SD-WAN Manager affecting the API interface. It allows authenticated remote attack…
CVE-2025-32975 🚨 Quest / KACE Systems Management Appliance (SMA)
CVE-2025-32975 is a critical authentication bypass vulnerability (CVSS 10.0) in Quest KACE Systems Management Appliance versions 13.0.x through 14.1.x, allowing…
CVE-2026-33634 🚨 Aquasecurity / Trivy
CVE-2026-33634 involves a supply chain attack against Aquasecurity's Trivy ecosystem, where compromised credentials were used to publish malicious versions of t…
CVE-2017-7921 🚨 Hikvision / Multiple Products
CVE-2017-7921 is a critical improper authentication vulnerability (CWE-287) affecting multiple Hikvision DS-2CD and DS-2DF series devices running firmware versi…
CVE-2025-64328 🚨 Sangoma / FreePBX
Sangoma FreePBX Endpoint Manager versions 17.0.2.36 through 17.0.3 contain a post-authentication command injection vulnerability in the filestore module's testc…
CVE-2026-23760 🚨 SmarterTools / SmarterMail
CVE-2026-23760 is a critical authentication bypass vulnerability in SmarterTools SmarterMail versions prior to build 9511, allowing unauthenticated attackers to…
CVE-2024-8069 🚨 Citrix / Session Recording
CVE-2024-8069 is a high-severity vulnerability in Citrix Session Recording that allows limited remote code execution with the privileges of a NetworkService acc…
CVE-2025-2775 🚨 SysAid / SysAid On-Prem
SysAid On-Prem versions 23.3.40 and earlier are vulnerable to an unauthenticated XML External Entity (XXE) flaw in the Checkin processing functionality, enablin…
CVE-2025-2776 🚨 SysAid / SysAid On-Prem
SysAid On-Prem versions up to 23.3.40 contain a critical unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, rat…
CVE-2025-20352 🚨 Cisco / IOS and IOS XE
CVE-2025-20352 is a stack overflow vulnerability in the SNMP subsystem of Cisco IOS and IOS XE Software, classified under CWE-121. It carries a CVSS v3.1 score …
CVE-2025-4428 🚨 Ivanti / Endpoint Manager Mobile (EPMM)
CVE-2025-4428 is a high-severity remote code execution vulnerability in the API component of Ivanti Endpoint Manager Mobile versions 12.5.0.0 and prior. It is c…
CVE-2025-31161 🚨 CrushFTP / CrushFTP
CVE-2025-31161 is a critical authentication bypass vulnerability in CrushFTP versions 10 before 10.8.4 and 11 before 11.3.1, allowing attackers to take over the…
CVE-2024-20439 🚨 Cisco / Smart Licensing Utility
CVE-2024-20439 is a critical authentication bypass vulnerability in Cisco Smart Licensing Utility (CSLU) caused by an undocumented static administrative credent…
CVE-2025-24472 🚨 Fortinet / FortiOS and FortiProxy
CVE-2025-24472 is a HIGH severity (CVSS 8.1) Authentication Bypass Using an Alternate Path or Channel vulnerability affecting FortiOS versions 7.0.0 through 7.0…
CVE-2023-20118 🚨 Cisco / Small Business RV Series Routers
CVE-2023-20118 is a command injection vulnerability in the web-based management interface of Cisco Small Business RV Series Routers (RV016, RV042, RV042G, RV082…
CVE-2025-24989 🚨 Microsoft / Power Pages
CVE-2025-24989 is a high-severity improper access control vulnerability in Microsoft Power Pages that allows unauthorized attackers to elevate privileges and by…
CVE-2025-0111 🚨 Palo Alto Networks / PAN-OS
CVE-2025-0111 is a medium severity (CVSS 6.5) authenticated file read vulnerability in Palo Alto Networks PAN-OS affecting the management web interface. It allo…
CVE-2018-19410 🚨 Paessler / PRTG Network Monitor
CVE-2018-19410 is a critical vulnerability in Paessler PRTG Network Monitor versions prior to 18.2.40.1683 that allows remote unauthenticated attackers to creat…
CVE-2024-55591 🚨 Fortinet / FortiOS and FortiProxy
CVE-2024-55591 is a critical authentication bypass vulnerability affecting FortiOS versions 7.0.0 through 7.0.16 and FortiProxy versions 7.0.0 through 7.0.19 an…
CVE-2021-44207 🚨 Acclaim Systems / USAHERDS
CVE-2021-44207 affects Acclaim USAHERDS versions through 7.4.0.1 due to the use of hard-coded credentials, classified under CWE-798. The vulnerability carries a…
CVE-2019-11001 🚨 Reolink / Multiple IP Cameras
CVE-2019-11001 is a command injection vulnerability affecting Reolink IP cameras including the RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W devices running …
CVE-2024-11680 🚨 ProjectSend / ProjectSend
CVE-2024-11680 is a critical improper authentication vulnerability (CWE-306) affecting ProjectSend versions prior to r1720, allowing remote unauthenticated atta…
CVE-2024-9474 🚨 Palo Alto Networks / PAN-OS
CVE-2024-9474 is a HIGH severity privilege escalation vulnerability (CWE-78) in Palo Alto Networks PAN-OS software, allowing authenticated administrators with m…
CVE-2024-0012 🚨 Palo Alto Networks / PAN-OS
CVE-2024-0012 is a critical authentication bypass vulnerability in Palo Alto Networks PAN-OS versions 10.2, 11.0, 11.1, and 11.2, allowing unauthenticated attac…
CVE-2024-37085 🚨 VMware / ESXi
VMware ESXi contains an authentication bypass vulnerability (CVE-2024-37085) classified under CWE-287 and CWE-305, allowing malicious actors with sufficient Act…
CVE-2023-45249 🚨 Acronis / Cyber Infrastructure (ACI)
CVE-2023-45249 is a critical remote code execution vulnerability in Acronis Cyber Infrastructure (ACI) caused by the use of default passwords, affecting builds …
CVE-2024-4040 🚨 CrushFTP / CrushFTP
CVE-2024-4040 is a critical server-side template injection vulnerability in CrushFTP versions prior to 10.7.1 and 11.1.0 across all platforms. It allows unauthe…
CVE-2023-6448 🚨 Unitronics / Vision PLC and HMI
CVE-2023-6448 is a critical vulnerability in Unitronics VisiLogic versions prior to 9.9.00, affecting Vision and Samba PLCs and HMIs, caused by the use of a def…
CVE-2023-22518 🚨 Atlassian / Confluence Data Center and Server
CVE-2023-22518 is a critical Improper Authorization vulnerability (CWE-863) affecting all versions of Atlassian Confluence Data Center and Server, allowing unau…
CVE-2023-20198 🚨 Cisco / IOS XE Web UI
CVE-2023-20198 is a critical vulnerability in Cisco IOS XE Software Web UI with a CVSS score of 10.0, allowing attackers to gain initial access and create local…
CVE-2023-22515 🚨 Atlassian / Confluence Data Center and Server
CVE-2023-22515 is a critical authentication bypass vulnerability in Atlassian Confluence Data Center and Server that allows external attackers to create unautho…
CVE-2023-42793 🚨 JetBrains / TeamCity
CVE-2023-42793 is a critical authentication bypass vulnerability in JetBrains TeamCity versions prior to 2023.05.4 that allows attackers to achieve remote code …
CVE-2023-28434 🚨 MinIO / MinIO
CVE-2023-28434 is a HIGH severity vulnerability (CVSS 8.8) in MinIO versions prior to RELEASE.2023-03-20T20-16-18Z that allows authenticated attackers to bypass…
CVE-2023-20269 🚨 Cisco / Adaptive Security Appliance and Firepower Threat Defense
CVE-2023-20269 is a medium severity vulnerability (CVSS 5.0) in Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) software affecting re…
CVE-2023-27532 🚨 Veeam / Backup & Replication
CVE-2023-27532 is a high-severity information disclosure vulnerability in Veeam Backup & Replication that allows attackers to obtain encrypted credentials from …
CVE-2024-57726 🚨 SimpleHelp / SimpleHelp
CVE-2024-57726 is a critical vulnerability in SimpleHelp remote support software versions 5.5.7 and earlier, allowing low-privilege technicians to create API ke…
CVE-2023-35081 🚨 Ivanti / Endpoint Manager Mobile (EPMM)
CVE-2023-35081 is a path traversal vulnerability (CWE-22) in Ivanti Endpoint Manager Mobile (EPMM) versions 11.10.x prior to 11.10.0.3, 11.9.x prior to 11.9.1.2…
CVE-2022-28810 🚨 Zoho / ManageEngine
CVE-2022-28810 is a critical remote code execution vulnerability in Zoho ManageEngine ADSelfService Plus versions prior to build 6122, allowing authenticated ad…
CVE-2018-5430 🚨 TIBCO / JasperReports
CVE-2018-5430 is a path traversal and information disclosure vulnerability in TIBCO JasperReports Server versions up to 6.4.2, allowing authenticated users to r…
CVE-2020-3433 🚨 Cisco / AnyConnect Secure
CVE-2020-3433 is a high-severity vulnerability in Cisco AnyConnect Secure Mobility Client for Windows that allows authenticated local attackers to perform DLL h…
CVE-2022-24706 🚨 Apache / CouchDB
CVE-2022-24706 is a critical vulnerability in Apache CouchDB versions prior to 3.2.2 that allows unauthenticated attackers to access improperly secured default …
CVE-2022-27925 🚨 Synacor / Zimbra Collaboration Suite (ZCS)
CVE-2022-27925 affects Zimbra Collaboration Suite (ZCS) versions 8.8.15 and 9.0, involving a directory traversal vulnerability in the mboximport functionality t…

Articles tagged with T1078 (30)

HIGH
CISA warns of cyberattacks targeting fuel tank monitoring systems
BleepingComputer · 2026-06-03
CRITICAL
Google DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RAT
The Hacker News · 2026-06-03
HIGH
AI accelerates development of ransomware toolkit with EDR evasion capabilities
SC Media · 2026-06-03
MEDIUM
Global Stock Exchange Hit by Monthslong Email Campaign
Dark Reading · 2026-06-03
HIGH
Argamal: Malware hidden in hentai games
Securelist · 2026-06-03
HIGH
Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign
Microsoft Security Blog · 2026-06-03
CRITICAL
Critical Kirki flaw exploited to hijack WordPress admin accounts
BleepingComputer · 2026-06-02
HIGH
SideCopy group targets Afghanistan's Ministry of Finance with Xeno RAT
SC Media · 2026-06-02
CRITICAL
Why supply chain attacks work and what detection can actually do about it
SC Media · 2026-06-02
CRITICAL
Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine
The Hacker News · 2026-06-02
HIGH
The HazyBeacon Protocol – How Malware Weaponizes Amazon Web Services (AWS) Lambda Function URLs
Qualys Research · 2026-06-02
MEDIUM
Russian spy agency says foreign spies turned officials' smartphones into surveillance devices
The Register Security · 2026-06-02
HIGH
LABScon25 Replay | Gamaredon x Turla: Unveiling a 2025 Espionage Alliance Targeting Ukraine
SentinelLabs · 2026-06-02
HIGH
Infected Red Hat npm packages expose developer credentials
CSO Online · 2026-06-02
HIGH
Meta AI Hands Over High-Profile Instagram Accounts to Hackers
SecurityWeek · 2026-06-02
HIGH
Pakistan-Linked SideCopy Targets Afghanistan Finance Ministry with Xeno RAT
The Hacker News · 2026-06-02
HIGH
Malware hides in Steam comments to infect WordPress sites
SC Media · 2026-06-01
HIGH
Red Hat npm packages compromised to steal developer credentials
BleepingComputer · 2026-06-01
CRITICAL
Dozens of Red Hat packages backdoored through its offical NPM channel
Ars Technica Security · 2026-06-01
HIGH
Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm
The Hacker News · 2026-06-01
MEDIUM
Russian hacker used AI to run fraud scheme on MAGA Telegram channel
SC Media · 2026-06-01
CRITICAL
FSB Group Gamaredon Hides Worm in Windows Data Streams
Infosecurity Magazine · 2026-06-01
MEDIUM
Election threats are focused on campaign systems, not voting machines
CyberScoop · 2026-06-01
HIGH
Malicious npm packages abuse dependency confusion to profile developer environments
Microsoft Security Blog · 2026-05-30
HIGH
Lone attacker published 14 malicious npm packages mimicking popular OpenSearch, Elasticsearch libraries
The Register Security · 2026-05-29
HIGH
AI helps Russian-speaking GreyVibe run five parallel attack chains on Ukrainian targets
SC Media · 2026-05-29
HIGH
‘Claude Code install’ search result leads to ClickFix infostealer attack
SC Media · 2026-05-29
HIGH
[NEU] [hoch] Froxlor: Mehrere Schwachstellen
BSI Germany · 2026-05-29
HIGH
Typosquatted npm packages used to steal cloud and CI/CD secrets
Microsoft Security Blog · 2026-05-29
HIGH
Typosquatted npm packages used to steal cloud and CI/CD secrets
Microsoft Security Blog · 2026-05-29